# China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)

> China-aligned, espionage-motivated actor TA419 is phishing U.S. AI policy experts at think tanks, universities, law firms and defense contractors, plus Japan-based organizations, by impersonating prominent AI figures and an Anthropic employee. Lures lead via shortened URLs and Cloudflare Turnstile-gated redirects to OneDrive-themed Microsoft sign-in pages that combine Evilginx-style AitM proxying with a modified Frameless BitB kit to capture credentials and live sessions.

- **Published:** 2026-10-04T00:00:00Z
- **Last reviewed:** 2026-10-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2884
- **ID:** TL-2026-2884
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** TA419 (China)
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Proofpoint reports that TA419, a China-aligned cyber-espionage actor active since at least April 2025, ran credential-phishing campaigns in February 2026 and July 2026 against people working on U.S. AI policy and regulation. In February 2026 the actor posed as a senior Anthropic employee and emailed an AI policy analyst at a U.S. think tank with the subject 'Request for Feedback on Military Integration of Claude'. In July 2026 (from July 8) it impersonated Lynne Edwards Parker, former Principal Deputy Director of the White House Office of Science and Technology Policy, and economist Heidi Crebo-Rediker, using mail.com and outlook.com sender addresses, inviting targets to a fictitious 'AI Policy Advisory Committee' or to contribute to a Senate Foreign Relations Committee report on AI export controls and supply chains.

The initial outreach is benign and builds trust. After a reply, the actor sends shortened URLs that pass through multi-stage redirection to first-stage domains (file-sharing themed), then a Cloudflare Turnstile check shown behind a fake OneDrive loading screen, and finally a second-stage adversary-in-the-middle (AitM) page. The kit uses a Microsoft 365 Evilginx-style phishlet with server-side substitution rules that inject scripts and HTML into proxied pages, relaying real Microsoft responses so the victim sees a genuine sign-in. A modified open-source Frameless BitB draws a fake browser window (HTML/CSS/JS, no iframe) over the OneDrive-styled page. A bespoke telemetry and automation module (/primary/script.js, /secondary/script.js, /secondary/observe.js) tracks and drives the victim through the Microsoft sign-in flow, including MFA, and auto-accepts the 'Keep me signed in' prompt. The target is Microsoft 365 / Entra ID via the OfficeHome client ID 4765445b-32c6-49b0-83e6-1d93765276ca. The result is capture of credentials, MFA codes and authenticated session cookies, enabling account takeover that passes conditional-access checks.

Infrastructure includes lookalike sender domains impersonating the Japan-Taiwan Exchange Association (tw-koryu.org), the Heritage Foundation (heritiages.org, heritiage.org) and a Japanese Minister of Defense site (shinjirou.info), eight first-stage and seven second-stage domains registered via NameSilo behind Cloudflare, an actor-controlled VPS at 108.61.163.187, and a TLS certificate with SHA256 b314a1499cd728ca3e54b7150661fd0c7d2279065fe3f570f0f66c395d744460 (subject C=US, ST=Kansas, L=Millsstad, O=Castro Inc, CN=CI). Targeting also covers defense contractors and Japan-based organizations. Proofpoint notes related AI-themed phishing previously reported as UNK_SweetSpecter. Coverage notes the report does not directly tie the activity to the Chinese government, which denies such allegations.

## MITRE ATT&CK

- T1583.001 Acquire Infrastructure: Domains
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1585.002 Establish Accounts: Email Accounts
- T1598.003 Phishing for Information: Spearphishing Link
- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1684.001 Impersonation
- T1557 Adversary-in-the-Middle
- T1539 Steal Web Session Cookie
- T1111 Multi-Factor Authentication Interception
- T1056.003 Input Capture: Web Portal Capture
- T1550.004 Use Alternate Authentication Material: Web Session Cookie
- T1090 Proxy

## Sources

- [Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles (Proofpoint)](https://www.proofpoint.com/us/blog/threat-insight/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-us-ai-policy)
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (The Hacker News)](https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html)
- [AI policy circles targeted in China-linked phishing operation (CyberScoop)](https://cyberscoop.com/china-cyber-espionage-ta419-phishing-us-ai-policy-experts/)
- [TA419 phishing campaign targeted AI policy experts (BetaNews)](https://betanews.com/article/ta419-phishing-campaign-ai-policy/)
- [China-Linked TA419 Hackers Target US AI Policy Experts With Credential Phishing Attacks (GBHackers)](https://gbhackers.com/china-linked-ta419-hackers-target-us-ai-policy-experts/)
- [TA419 Targets AI Policy Experts with BitB and Evilginx AiTM Phishing (DEV Community)](https://dev.to/anoymask/ta419-targets-ai-policy-experts-with-bitb-and-evilginx-aitm-phishing-k2l)
- [Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles (Hendry Adrian mirror)](https://www.hendryadrian.com/hallucinating-credibility-china-aligned-ta419-impersonates-its-way-into-us-ai-policy-circles/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2884
